Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution  
Forum Quick Jump
 
New Topic Post reply to : PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution Printable version of : PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
34 posts in this thread.
Viewing Page :
 1  2 
[ << Previous Thread | Next Thread >> ]

Khiz
New Member


Date Joined Dec 2008
Total Posts : 5
 
   Posted 12-9-2008 7:46 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
So I've had this problem for the past weekend, and I just followed all the advice on this page. I was able to get it to run the scan and it detected threats and when I tried to remove, it said to restart in order for them to remove. I did that and re-scanned and they were still there. I rebooted in safe mode with netowrking and did it there, removed and restarted and re-did it in regular mode and same thing happened. Here are the screen caps of my last attempt: Can someone tell me what to do next to remove them?

Cap 1:





Back to Top
 

LoriHasAVirus
New Member


Date Joined Dec 2008
Total Posts : 2
 
   Posted 12-14-2008 4:40 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
I'm trying to run this fix. I was able to reboot in Safe Mode earlier when I was trying some alternative fixes (before I found this). Now, I'm trying to reboot in Safe Mode and it gets to the MS Windows XP "Windows is starting up" and then freezes. Any advice?
Thanks for your help!
Back to Top
 

BDiggins1
New Member


Date Joined Dec 2008
Total Posts : 1
 
   Posted 12-14-2008 7:41 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
LoriHasAVirus, I had a similar issue earlier and came across the fix.... I'm having a magic weekend trying to sort this out!! Anyway, before going to safe mode, boot up as normal and try the following:

* Click on Start, click Run, and then type devmgmt.msc and click OK
* On the View menu click on Show hidden devices
* Browse to Non-Plug and Play Drivers and you should see something like TDSSserv.sys
* Highlight that driver and right click on it and select DISABLE - NOT uninstall.
* Now RESTART your computer.

And boot into Safe Mode.


P.S. if you can't boot into normal mode, and it's freezing, you will have to have your recovery disk in your cd/dvd drive, so that it uses the disc to boot up into normal mode...it's been a long time since I came across such a malicious piece of s@#t!!
Back to Top
 

LoriHasAVirus
New Member


Date Joined Dec 2008
Total Posts : 2
 
   Posted 12-14-2008 3:53 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Thanks for the help. I was able to reboot in Safe Mode (without networking) and run the anti-malware software. I had to run it twice because it wasn't able to delete all the files and I had to restart my computer. After running it twice and deleting all the infected files, I'm still unable to run my computer in normal mode. It starts up and then there's this message on my desktop about restoring my active desktop. Before I can finish reading anything, I get a blue DOS looking screen and the laptop quickly powers down and then restarts. Humm... Any thoughts about this one?
Back to Top
 

china closets
New Member


Date Joined Dec 2008
Total Posts : 1
 
   Posted 12-22-2008 6:55 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
I also had the problem, and using what I found on this site, I was able to fix it. I just wanted to say that I had a problem with going into safe mode as I couldn't log in there, when I tried logging in with my username it wouldn't work, it would say that my username has been disabled, and when I only used malwarebytes in regular mode, it didnt eliminate the problem, so I went into regedit, and searched for TDSSeoqh.dll and I found it in a folder in windows search assistant, I just deleted the whole folder, and now my computer works great!!! I don't have any of my old problems!!
Back to Top
 

killertrojan
New Member


Date Joined Jan 2009
Total Posts : 2
 
   Posted 1-2-2009 9:32 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution


I have some further info on this. MAybe a mod could add more. i have a similar trojan which is killing me and I like all of you could not get malwarebytes to run. I tried everything suggested. My administrator account had a password that i must have put in years ago and forgot about. However I did have another administrator account i set up for my son and forgot about. I installed with the above instructions there and it worked great. The program found nothing and I still get redirected explorer which shuts down when i try to connect to antivirus sights. it even turns off my vshield . There is no way of knowing which trojan i have since it all comes up clean but thought i would pass this along to help someone else.
if you can not get malwarebytes  to run try creating a new administrator account ( provided you are at administrator level of course ) and see if it will install and run that way.


i do not know why but my malwarebytes used to run before then stopped. Who knows. maybe it is my virus checker that is stopping malware bytes from running.
I am wondering now if this new account i created will stillhave the same issues. hmmmm.......


Back to Top
 

killertrojan
New Member


Date Joined Jan 2009
Total Posts : 2
 
   Posted 1-2-2009 9:34 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
ps .. anyone know how i can reset my main admin password ? the account doesn't even show in the users section.
Back to Top
 

dds118
New Member


Date Joined Jan 2009
Total Posts : 1
 
   Posted 1-8-2009 4:01 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
I have been trying this fix, and followed all steps.  Unfortunately, it does not seem to ever finish installing (I am at almost 2 hours, and the folder I have it installing to is blank).  would it work to run install (setup.exe) from Safe mode?  Should I pull out and try again?


Back to Top
 

cokeonice
New Member




Date Joined Feb 2009
Total Posts : 1
 
   Posted 2-5-2009 5:14 (GMT +1)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
I tried the OP's method.  I had actually thought of this on my own but did not go as far as OP waiting a long time for the installation to finish.  Anyway, the OP's method does not work anymore.  The virus' author has found a way to circumvent this.
 
First download Avira ISO and burn it to a CD.
 
Then download a Linux ISO called SytemRescueCD.
 
Create bootable CD's with these ISO's.
 
Boot your PC with the Avira CD and scan your computer.  When it is done, scroll up through the log and write down all of the virus filenames Avira found including the directory paths where it found them.  Select the option to restart your PC.
 
While the PC is starting to reboot, replace the Avira bootable CD with the SystemRescueCD and let the PC boot with that CD.
 
Once the SystemRescueCD has finished booting, mount your hard-drive according to the instructions, change directory to your mounted hard-drive, change directory to WINDOWS, change directory to system32, run this command:
 
ntfs-3g /dev/sda1 /mnt/windows
 
cd /mnt/windows
 
cd WINDOWS
 
cd system32
 
To remove the TDSS virus that the OP is talking about, enter this command to see if they are there:
 
dir TDSS*.*
 
You should see at least seven files.  To get rid of them enter this command:
 
rm TDSS*.* -f
 
Then from the "system32" folder change directory to the "drivers" folder and run the above command again:
 
cd drivers
 
rm TDSS*.* -f
 
Now, if Avira found any other virus', go to those directory's and delete those files as well.  To get Malwarebytes to install normally though, you should only have to remove TDSS.
 
Now, to change directory back to the Linux root (get off your hard-drive) and unmount the hard-drive enter these commands:
 
cd /
 
umount /mnt/windows
 
Then restart the PC by entering this command:
 
shutdown -r now
 
As the PC is restarting, remove the CD, let the machine boot into Windows, and then run the Malwarebytes removal program.
 
If anyone needs more detailed instructions, such as "How do I burn an ISO to a CD?", send me a message.  Google is your friend.

Post Edited (cokeonice) : 05-02-2009 16:44:05 GMT

Back to Top
 
New Topic Post reply to : PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution Printable version of : PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
34 posts in this thread.
Viewing Page :
 1  2 
 
Forum Information
Currently it is Saturday, November 21, 2009 1:13 PM (GMT +1)
There are a total of 73.031 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 70 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
32 Guest(s), 1 Registered Member(s) are currently online.  Details
urbane
5 Latest Threads
Constant scanning andskipped files? (1)21-11-2009 10:08:33 (Dickens)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)
Atlanta Falcons Jerseys (0)21-11-2009 06:15:26 (donejerseys)